Eleytt Research www.eleytt.com Overview: ==================== Michal Bucko, Eleytt, www.eleytt.com/michal.bucko Shyaam Sundhar, Eleytt Tomasz Galdys, Eleytt Credit: ==================== Michal Bucko, Eleytt, www.eleytt.com/michal.bucko Vulnerability Table =================== 1. Windows Calendar (Vista) ICS File Denial of Service Vulnerability 2. Toolbar vulnerabilities: a) Toolbar Gaming IE Toolbar Denial of Service Vulnerability b) ExportNation IE Toolbar Denial of Service Vulnerability c) Advanced Searchbar Denial of Service Vulnerability Information Table ================= 1. OpenOffice 2.2 Multiple File Extensions Handling Denial of Service Issue Vulnerability Details ========================= ========================= 1. Windows Calendar (Vista) ICS File Denial of Service Vulnerability ================================================================= Specially malformed ISC file, once imported to Windows Calendar, leads to Windows Calendar to a crash (after the remainder is set). Windows Calendar crashes every each time Vista is rebooted. The vulnerability stems from NULL pointer dereference and has been confirmed on fully updated Windows Vista. Successful at MSRC has been informed and confirmed the situation. Both, Eleytt and MSRC consider this issue of low impact. 2. Toolbar vulnerabilities ======================= a) The vulnerability in 'CallCmd' function in toolbar_gaming.dll has its roots in NULL pointer dereference, which results in denial of service conditions. b) The vulnerability lies in Toolbar.DLL library, in 'isChecked' function. The registers' values are below: EIP 01838C70 EAX 00000000 . ESP 001BA90C -> Asc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA The crash itself happens here: 1838C70 MOV ECX,[EAX+188] Stack dump is full of 'A', but SEH hasn't been overwritten. The problem lies in NULL pointer dereference. The vulnerability, therefore, hasn't been proven exploitable. Arbitrary code execution is probably impossible. c) The vulnerability lies in Toolbar.DLL library, in 'isChecked' function. The exactly the same kind of vulnerability that described in b). Information Table ================= 1. OpenOffice 2.2 Multiple File Extensions Handling Denial of Service Issue ======================================================================== An issue in OpenOffice 2.2 Multiple File Extension Handling leads to denial of service conditions. Due to the minimum severity of the issue, the information is provided in Information Table. The issue does not allow code execution. Eleytt provides exemplary PoC exploits for this issue for reponsible security companies only. 